New Chef InSpec 2.0 delivers open source compliance to accelerate DevSecOps; reduce assessment and remediation time

Chef, provider of continuous automation solutions, announced on Tuesday InSpec 2.0, a compliance automation solution that accelerates DevSecOps by allowing cross-functional application, infrastructure and security teams to assess and remediate compliance issues from development through the entire software delivery lifecycle.

InSpec 2.0 provides cloud configuration testing (including Microsoft Azure and AWS), more than 30 new conformance capabilities (including Docker, IIS, NGINX and PostgreSQL), enhanced integration with third-party tools and improved ease-of-use and customizability.

InSpec 2.0 gives users the ability to write compliance rules against cloud resources, including AWS and Microsoft Azure, with user-defined custom compliance policies. It also contains over 30 new resources, allowing users to write compliance rules for many common applications and configuration files without requiring any programming knowledge. These include Docker, security keys (RSA/DSA/x509), webserver (IIS/nginx/Apache) configurations, packages (both system as well as Perl/R/etc.), PostgreSQL and MySQL database configurations, XPath matching in XML config files, ZFS storage pool configurations and many more.

InSpec results can now be exported as JUnit format for integration into continuous delivery tools such as Jenkins and can pull compliance profiles from Chef Automate. Previously-announced integration with Amazon Systems Manager (SSM) provides a frictionless on-ramp to InSpec in the cloud. InSpec 2.0 runs 90 percent faster than InSpec 1.0 on Windows and 30 percent faster on Linux.

InSpec is an initial step in Chef’s ‘Detect, Correct, Automate’ approach to cloud migration and continuous automation. It helps organizations maintain an up-to-date view of compliance status in production, detect security issues long before they reach production and reduce risk while delivering applications faster.

An open-source framework for describing security and compliance rules that can be shared between software engineers, operations and security engineers, InSpec enables compliance at velocity at all stages of the software delivery process, from the developer’s workstation all the way to production, with no performance impact or side-effects. InSpec’s readability means it is easy to use and understand for all team members, including those whose roles involve minimal coding.

A recent survey of more than 1,500 users conducted by Chef found that 74 percent of cross-functional application, infrastructure and security teams assess software for compliance manually prior to production. Once violations and vulnerabilities are discovered, half remediate manually instead of automating the process. Manual processes result in teams’ detecting and remediating security issues in days (31 percent) or weeks (19 percent), instead of hours (18 percent).

As a recent paper from SANS Institute notes, “To scale in a large hybrid or public cloud, security will need to embrace automation, a concept that many security practitioners have been loath to embrace. For true DevSecOps to take hold, security teams will need to embed automated tests and validation of controls into the deployment cycle and monitor applications continuously in production with triggered responses that can roll controls back to a known good state, among other outcomes.”

“InSpec has helped us unify our compliance, security and DevOps teams and streamlined audits, reducing the thousands of staff hours usually required by as much as 95 percent and eliminating duplication of effort and data throughout the process,” said Jon Williams, CTO of niu Solutions. “It has given these teams more control over compliance policies and enabled business units to be more active in maintaining their own environments. Most critically, it allows us to continually monitor for audit compliance, ensuring desired state and eliminating change drift between nodes.”

“InSpec 2.0 builds on our commitment to build the essential tools and services needed for modern application teams to truly deliver on the promise of DevSecOps, fully integrating security with development and deployment for traditional and cloud-native software delivery,” said Marc Holmes, VP of marketing at Chef. “InSpec provides an easy-to-learn, open-source path to incorporating security and compliance requirements as code directly with the delivery process, ensuring that applications and infrastructure are compliant every step of the way — not just at the end of the process.”

Leave a Reply

WWPI – Covering the best in IT since 1980